Re: [WebDNA] path traversal

This WebDNA talk-list message is from

2020


It keeps the original formatting.
numero = 115088
interpreted = N
texte = 2717 --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Good on you. As long as WSC doesn=E2=80=99t munge the old commerce tags = / contexts (no guarantees that they are not already messed with), you = should=20 be good for awhile. That old commerce system is one of the main reasons = why I (and many) fell in love with WebDNA=E2=80=A6 but it hasn=E2=80=99t = been improved on nor supported since 2012 or so. Donovan > On Apr 14, 2020, at 11:59 AM, talk@webdna.us wrote: >=20 > It=E2=80=99s actually the oldest running eShop for computer hardware = in Israel launched in 1997 with WebCatalog on Mac OS (PowerPC) > and 2-3 years ago moved to CentOS and WebDNA enterprise. > The WebDNA runs great will all the ^ and all the other weird stuff and = the site is super solid and fast for decades > And also new code is added all the time for the last 22 years and now = this issue also solved >=20 > No reason to change nothing. Same URLs for 22 years is something = Google adore. >=20 > Yours, >=20 > Yariv >=20 >=20 >> On 14 Apr 2020, at 12:19, talk@webdna.us wrote: >>=20 >> As far as I know the old (but awesome) e-commerce system is no longer = supported.=20 >>=20 >> Every commerce context for that old e-commerce system (orderfile, = addlitems, etc) had path parameter options... (so, for example = =E2=80=98file=3D^=E2=80=99). >>=20 >> =E2=80=98^=E2=80=99 symbol is the path to the globals directory. = (Which is also, I believe, said to be unsupported)=20 >>=20 >> I=E2=80=99d suggest finding a new solution.. but if you are sticking = with ancient technology, find a copy of the older docs. Good luck=20 >>=20 >>=20 >>=20 >> D. Brooke Mobile >>=20 >>> On Apr 14, 2020, at 2:55 AM, talk@webdna.us wrote: >>>=20 >>> =EF=BB=BFA security friend told me about "path traversal=E2=80=9D=20 >>> https://portswigger.net/web-security/file-path-traversal >>>=20 >>> and told me that the idea that the =E2=80=9CShoppingCarts=E2=80=9D = folder is located usually under a website folder is not a good practice. >>> How do i move the creation of files from the directory under the = website forlder to be under the Globals so it=E2=80=99ll be protected = from such kind of attack ? >>>=20 >>> I made such directory elsewhere but didn=E2=80=99t know how to make = WebDNA use it ? >>>=20 >>> I use CentOS 7 and=20 >>>=20 >>> Yours, >>>=20 >>> Yariv--------------------------------------------------------- >>> This message is sent to you because you are subscribed to >>> the mailing list talk@webdna.us >>> To unsubscribe, E-mail to: talk-leave@webdna.us >>> archives: http://www.webdna.us/page.dna?numero=3D55 >>> Bug Reporting: support@webdna.us >>=20 >> --------------------------------------------------------- >> This message is sent to you because you are subscribed to >> the mailing list talk@webdna.us >> To unsubscribe, E-mail to: talk-leave@webdna.us >> archives: http://www.webdna.us/page.dna?numero=3D55 >> Bug Reporting: support@webdna.us >=20 > --------------------------------------------------------- > This message is sent to you because you are subscribed to > the mailing list talk@webdna.us > To unsubscribe, E-mail to: talk-leave@webdna.us > archives: http://www.webdna.us/page.dna?numero=3D55 > Bug Reporting: support@webdna.us Donovan Brooke Owner - EUCA (608) 770-3822 355 E State St. APT 8 Iola, WI 54945 --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 Good = on you. As long as WSC doesn=E2=80=99t munge the old commerce tags / = contexts (no guarantees that they are not already messed with), you = should 
be good for awhile. That old commerce system = is one of the main reasons why I (and many) fell in love with WebDNA=E2=80= =A6 but it hasn=E2=80=99t been improved on nor supported since 2012 or = so.

Donovan



On Apr 14, 2020, at 11:59 AM, = talk@webdna.us = wrote:

It=E2=80=99s actually the oldest running eShop for computer = hardware in Israel launched in 1997 with WebCatalog on Mac OS = (PowerPC)
and 2-3 years ago moved to CentOS and WebDNA = enterprise.
The WebDNA runs great will all the ^ and all = the other weird stuff and the site is super solid and fast for = decades
And also new code is added all the time for the = last 22 years and now this issue also solved

No reason to change nothing. Same URLs for 22 years is = something Google adore.

Yours,

Yariv


On 14 Apr 2020, at = 12:19, talk@webdna.us = wrote:

As far as I know the old (but = awesome) e-commerce system is no longer supported.

Every commerce context for that old e-commerce system = (orderfile, addlitems, etc) had path parameter options... (so, for = example =E2=80=98file=3D^=E2=80=99).

=E2=80=98= ^=E2=80=99 symbol is the path to the globals directory. (Which is also, = I believe, said to be unsupported)

I=E2=80=99= d suggest finding a new solution.. but if you are sticking with ancient = technology, find a copy of the older docs. Good luck



D. Brooke Mobile

On Apr = 14, 2020, at 2:55 AM, talk@webdna.us wrote:

=EF=BB=BF= A security friend told me about "path traversal=E2=80=9D
https://portswigger.net/web-security/file-path-traversal
and told me that the idea that the = =E2=80=9CShoppingCarts=E2=80=9D folder is located usually under a = website folder is not a good practice.
How do i move the = creation of files from the directory under the website forlder to be = under the Globals so it=E2=80=99ll be protected from such kind of attack = ?

I made such directory elsewhere but = didn=E2=80=99t know how to make WebDNA use it ?

I use CentOS 7 and

Yours,

Yariv---------------------------------------------------------<= br class=3D"">This message is sent to you because you are subscribed = to
the mailing list talk@webdna.us
To = unsubscribe, E-mail to: talk-leave@webdna.us
archives: = http://www.webdna.us/page.dna?numero=3D55
Bug Reporting: = support@webdna.us

---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: = talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us

---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: = talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us

Donovan Brooke
Owner - = EUCA
(608) 770-3822

355 E State St. APT 8
Iola, WI = 54945



= --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: support@webdna.us --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7-- . Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] path traversal (Donovan Brooke 2020)
  2. Re: [WebDNA] path traversal (Office 2020)
  3. Re: [WebDNA] path traversal (Office 2020)
  4. Re: [WebDNA] path traversal (Stuart Tremain 2020)
  5. Re: [WebDNA] path traversal (Stuart Tremain 2020)
  6. Re: [WebDNA] path traversal (Donovan Brooke 2020)
  7. [WebDNA] path traversal (Yariv Nachshon 2020)
2717 --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Good on you. As long as WSC doesn=E2=80=99t munge the old commerce tags = / contexts (no guarantees that they are not already messed with), you = should=20 be good for awhile. That old commerce system is one of the main reasons = why I (and many) fell in love with WebDNA=E2=80=A6 but it hasn=E2=80=99t = been improved on nor supported since 2012 or so. Donovan > On Apr 14, 2020, at 11:59 AM, talk@webdna.us wrote: >=20 > It=E2=80=99s actually the oldest running eShop for computer hardware = in Israel launched in 1997 with WebCatalog on Mac OS (PowerPC) > and 2-3 years ago moved to CentOS and WebDNA enterprise. > The WebDNA runs great will all the ^ and all the other weird stuff and = the site is super solid and fast for decades > And also new code is added all the time for the last 22 years and now = this issue also solved >=20 > No reason to change nothing. Same URLs for 22 years is something = Google adore. >=20 > Yours, >=20 > Yariv >=20 >=20 >> On 14 Apr 2020, at 12:19, talk@webdna.us wrote: >>=20 >> As far as I know the old (but awesome) e-commerce system is no longer = supported.=20 >>=20 >> Every commerce context for that old e-commerce system (orderfile, = addlitems, etc) had path parameter options... (so, for example = =E2=80=98file=3D^=E2=80=99). >>=20 >> =E2=80=98^=E2=80=99 symbol is the path to the globals directory. = (Which is also, I believe, said to be unsupported)=20 >>=20 >> I=E2=80=99d suggest finding a new solution.. but if you are sticking = with ancient technology, find a copy of the older docs. Good luck=20 >>=20 >>=20 >>=20 >> D. Brooke Mobile >>=20 >>> On Apr 14, 2020, at 2:55 AM, talk@webdna.us wrote: >>>=20 >>> =EF=BB=BFA security friend told me about "path traversal=E2=80=9D=20 >>> https://portswigger.net/web-security/file-path-traversal >>>=20 >>> and told me that the idea that the =E2=80=9CShoppingCarts=E2=80=9D = folder is located usually under a website folder is not a good practice. >>> How do i move the creation of files from the directory under the = website forlder to be under the Globals so it=E2=80=99ll be protected = from such kind of attack ? >>>=20 >>> I made such directory elsewhere but didn=E2=80=99t know how to make = WebDNA use it ? >>>=20 >>> I use CentOS 7 and=20 >>>=20 >>> Yours, >>>=20 >>> Yariv--------------------------------------------------------- >>> This message is sent to you because you are subscribed to >>> the mailing list talk@webdna.us >>> To unsubscribe, E-mail to: talk-leave@webdna.us >>> archives: http://www.webdna.us/page.dna?numero=3D55 >>> Bug Reporting: support@webdna.us >>=20 >> --------------------------------------------------------- >> This message is sent to you because you are subscribed to >> the mailing list talk@webdna.us >> To unsubscribe, E-mail to: talk-leave@webdna.us >> archives: http://www.webdna.us/page.dna?numero=3D55 >> Bug Reporting: support@webdna.us >=20 > --------------------------------------------------------- > This message is sent to you because you are subscribed to > the mailing list talk@webdna.us > To unsubscribe, E-mail to: talk-leave@webdna.us > archives: http://www.webdna.us/page.dna?numero=3D55 > Bug Reporting: support@webdna.us Donovan Brooke Owner - EUCA (608) 770-3822 355 E State St. APT 8 Iola, WI 54945 --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 Good = on you. As long as WSC doesn=E2=80=99t munge the old commerce tags / = contexts (no guarantees that they are not already messed with), you = should 
be good for awhile. That old commerce system = is one of the main reasons why I (and many) fell in love with WebDNA=E2=80= =A6 but it hasn=E2=80=99t been improved on nor supported since 2012 or = so.

Donovan



On Apr 14, 2020, at 11:59 AM, = talk@webdna.us = wrote:

It=E2=80=99s actually the oldest running eShop for computer = hardware in Israel launched in 1997 with WebCatalog on Mac OS = (PowerPC)
and 2-3 years ago moved to CentOS and WebDNA = enterprise.
The WebDNA runs great will all the ^ and all = the other weird stuff and the site is super solid and fast for = decades
And also new code is added all the time for the = last 22 years and now this issue also solved

No reason to change nothing. Same URLs for 22 years is = something Google adore.

Yours,

Yariv


On 14 Apr 2020, at = 12:19, talk@webdna.us = wrote:

As far as I know the old (but = awesome) e-commerce system is no longer supported.

Every commerce context for that old e-commerce system = (orderfile, addlitems, etc) had path parameter options... (so, for = example =E2=80=98file=3D^=E2=80=99).

=E2=80=98= ^=E2=80=99 symbol is the path to the globals directory. (Which is also, = I believe, said to be unsupported)

I=E2=80=99= d suggest finding a new solution.. but if you are sticking with ancient = technology, find a copy of the older docs. Good luck



D. Brooke Mobile

On Apr = 14, 2020, at 2:55 AM, talk@webdna.us wrote:

=EF=BB=BF= A security friend told me about "path traversal=E2=80=9D
https://portswigger.net/web-security/file-path-traversal
and told me that the idea that the = =E2=80=9CShoppingCarts=E2=80=9D folder is located usually under a = website folder is not a good practice.
How do i move the = creation of files from the directory under the website forlder to be = under the Globals so it=E2=80=99ll be protected from such kind of attack = ?

I made such directory elsewhere but = didn=E2=80=99t know how to make WebDNA use it ?

I use CentOS 7 and

Yours,

Yariv---------------------------------------------------------<= br class=3D"">This message is sent to you because you are subscribed = to
the mailing list talk@webdna.us
To = unsubscribe, E-mail to: talk-leave@webdna.us
archives: = http://www.webdna.us/page.dna?numero=3D55
Bug Reporting: = support@webdna.us

---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: = talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us

---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: = talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us

Donovan Brooke
Owner - = EUCA
(608) 770-3822

355 E State St. APT 8
Iola, WI = 54945



= --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: support@webdna.us --Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7-- . Donovan Brooke

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

New syntax feedback for 4.0 (2000) # fields limited? (1997) WebCat2 - Getting to the browser's username/password data (1997) Database flushing does not work any more... (2000) Initiating NewCart (1997) WebSTAR 2.1 freezes my Mac (1997) Can WebCatalog.debug solve my problem? (2000) Part Html part WebDNA (1997) take me off mailing list please (2001) Migrating to NT (1997) Forumulas.db & Variables (2002) Database Path (1998) Bug Report, maybe (1997) [SHOWIF AND/OR] (1997) syntax question, not in online refernce (1997) Why is [authenticate] not recognizing [username] on all sitedirectories? (2000) [WebDNA] WebDNA Sciprt for Zipping files? (2012) Extended [ConvertChars] (1997) HomePage Caution (1997) Multiple cart additions (1997)